Vulnerabilities > CVE-2006-6424 - Heap Overflow vulnerability in Novell Netmail IMAP Verb Literal

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
novell
critical
exploit available
metasploit

Summary

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow. Successful exploitation requires a valid user account. This vulnerability is addressed in the following product update: Novell, NetMail, 3.52e FTF2

Exploit-Db

descriptionNovell NetMail. CVE-2006-6424. Remote exploit for windows platform
idEDB-ID:16813
last seen2016-02-02
modified2010-05-09
published2010-05-09
reportermetasploit
sourcehttps://www.exploit-db.com/download/16813/
titleNovell NetMail <= 3.52d NMAP STOR Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in Novell's Netmail 3.52 NMAP STOR verb. By sending an overly long string, an attacker can overwrite the buffer and control program execution.
idMSF:EXPLOIT/WINDOWS/NOVELL/NMAP_STOR
last seen2020-02-29
modified2017-07-24
published2007-03-01
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6424
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/novell/nmap_stor.rb
titleNovell NetMail NMAP STOR Buffer Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83015/nmap_stor.rb.txt
idPACKETSTORM:83015
last seen2016-12-05
published2009-11-26
reporterMC
sourcehttps://packetstormsecurity.com/files/83015/Novell-NetMail-3.52d-NMAP-STOR-Buffer-Overflow.html
titleNovell NetMail <= 3.52d NMAP STOR Buffer Overflow

Saint

bid21725
descriptionNovell NetMail NMAP STOR command buffer overflow
idmail_imap_netmailneg
osvdb31363
titlenetmail_nmap_stor
typeremote